CVE-2022-22524
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
28/09/2022
Last modified:
28/10/2022
Description
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an unauthenticated remote attacker could utilize a SQL-Injection vulnerability to gain full database access, modify users and stop services .
Impact
Base Score 3.x
9.40
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:gavazziautomation:cpy_car_park_server:*:*:*:*:*:*:*:* | 2.8.3 (excluding) | |
| cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:*:*:*:*:*:* | 8.5.0.3 (excluding) | |
| cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:edp:*:*:*:*:* | 8.5.0.3 (excluding) | |
| cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:edp:*:*:*:*:* | ||
| cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:security_enhanced:*:*:*:*:* | 8.5.0.3 (excluding) | |
| cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:security_enhanced:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



